@patrickcmiller
There is something off here:
1. There never was a claim for FIDO2 being MITM resistant.
2. FIDO2 isn't even attacked at all, but other parts of the system
3. Even those systems are attacked outside of the established security models (mainly, that TLS works and the browser's session storage is not hijacked).
In other words: Even the most secure door lock does not protect against burglars blowing up the roof. There is no surprise here.